Technology by Design

Technology news, reviews, and how to keep your technology running fast and smooth!

  • Home
  • About TbyD
    • Who is TbyD
    • Why Choose TbyD?
    • 16 Things
    • Your Computer Guy
  • Products and Services
    • Business Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
      • Performance Analysis
      • Optimization
      • Core Security Solution
      • Managed Backups
      • Computer and Network Systems
      • Computer Setup
      • Domain Names
      • Email Services
      • Extended Warranties
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
      • Websites
    • Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
        • Computer Setup
      • Core Security Solution
      • Managed Backups
      • Extended Warranties
      • Performance Analysis
      • Optimization
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
    • Products
      • Computers
      • Servers
  • Testimonials
    • What Our Clients Say About Us
  • Blogs
    • ALERTS
    • FAQ
    • How To Videos
  • Newsletters
    • TechTips Newsletters
  • Reviews
  • Media
    • Email Red Flags
    • E-Books
    • Disaster Prevention Planning Kit
    • Free Reports
  • Contact Us
    • Contact Us
    • Quick Support

ALERT: WordPress Website Hack

February 9, 2016 by The T By D Team Leave a Comment

WordPress Hack

ALERT:  WordPress Website Hack

 

An alarming number of websites built with popular website-building tool, WordPress, have been hacked, and are delivering the TeslaCrypt ransomware to unsuspecting victims.  

Malware researchers from Malwarebytes and other security firms have reported that a massive number of legit WordPress sites have somehow been compromised, and are silently redirecting visitors to sites with Nuclear Exploit Kit.  As of press time, it is unclear how the WordPress websites are getting infected, but is highly likely that there is a new vulnerability that is being exploited in either WordPress, or one of its plugins.

Malwarebytes Senior Security Researcher Jérôme Segura stated in a blog released last week:

“WordPress sites are injected with huge blurbs of rogue code that perform a silent redirection to domains appearing to be hosting ads.  This is a distraction (and fraud) as the ad is stuffed with more code that send visitors to the Nuclear Exploit Kit.”

The attack tries to conceal itself, and the code forces visitors to be redirected through a series of sites before dropping the ransomware payload.  Once a WordPress server is infected, the malware also installs a variety of backdoors on the machine.askimet Hack Files

 

What to do if You Run WordPress:Update No Excuses
  1. Update server Operating Systems (OS).
  2. Update WordPress.
  3. Delete any plugins you are not actively using, and update patches on any plugins you currently use.
  4. Update all your WordPress instances at the same time to prevent cross-infections.  
  5. Lock down all WordPress instances with a very strong password, as well as the WordPress 2-factor authentication
How to Protect Your Website Visitors:
  1. Keep workstation Operating Systems (OS) and 3rd party apps updated at all times.
  2. Backup your data and keep daily off-site backups.  TEST your backups, and if your restore function actually works (this is often overlooked).
  3. Provide end-users with the 64-bit version of Google Chrome if possible.
  4. Run the latest V5.5 of Microsoft’s Enhanced Mitigation Experience Toolkit (EMET) on workstations.
  5. Provide Security Awareness Training.No Backups
Not sure if your company is safe?  Ask us for a FREE Network Security Assessment!

Check out our “Email Red Flags”  for what to watch for in suspicious emails. 

Ask us about our “Core Security Solutions” package!
You can’t stop CyberCriminals from targeting your company or employees.
But you can be prepared for their arrival, and have full shields up.

Got CyberBugs?

Call 1-204-800-3166

For Cyber-Extermination!

#itthatworks

Filed Under: ALERTS, Featured

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Sign Up For The Monthly TechTips Newsletter!

* = required field
unsubscribe from list

powered by MailChimp!

Recent Posts

  • ALERT: Celebrity Death Scams
  • ALERT: Uber Hacked
  • ALERT: Netflix Email Scam
  • ALERT: Bad Rabbit
  • Scam – Reset Password Alert

Recent Comments

  • ALERT: New Ransomware Targets MS Office 365 Users - Technology by Design on Managed Backups
  • ALERT: FBI Warns Email Extortion Heating Up for Summer! - Technology by Design on ALERT: AshleyMadison Hack Blows Up
  • ALERT: Evil Android Trojan Empties Your Bank Account - Technology by Design on Definition: Phishing
  • ALERT: HTML Attachments - Technology by Design on Definition: Phishing
  • ALERT: New Ransomware Also Steals Your Bitcoins - Technology by Design on Managed Backups

Copyright © 2025 · Dynamik Website Builder on Genesis Framework · WordPress · Log in